Malicious AI Skills Are Increasingly Stealing Credentials at Scale

Cybercriminals are exploiting AI agent skills to steal sensitive credentials, with some malware-ridden skills reaching over 1.7 million installs. Immediate manual removal is critical.

Malicious AI Skills Are Increasingly Stealing Credentials at Scale
Sarah Collins

Sarah Collins

Computing Editor

Specializes in PCs, laptops, components, and productivity-focused computing tech.

Malicious manipulation of AI agent skills poses a significant and growing cybersecurity risk. AI skills, essentially small programs or instructions that empower AI agents to perform tasks, have become targets for cybercriminals using a sophisticated form of supply-chain attack.

How Are Malicious AI Skills Compromising Security?

Attackers are cloning legitimate AI skills and uploading visually similar typosquatted versions to public AI skill registries. Initially, these cloned skills appear benign, increasing their download counts and gaining user trust. Later, attackers update them to include malicious code that commands AI agents to extract sensitive data such as SSH keys, cloud and database credentials, token files, and infrastructure configurations. These credentials are then gathered and sent to attackers, exposing users and organizations to data breaches and potential unauthorized access.

Scope and Impact of This Threat

One of China's Most Powerful AI Models Has Also Escaped Containment | WIRED
One of China's Most Powerful AI Models Has Also Escaped Containment | WIRED

Investigations reveal that at least one family of malicious AI skills has reached over 1.7 million total downloads, indicating widespread exposure. Additionally, dozens of other dangerous AI skills continue to proliferate, some even deploying secondary malware payloads. This evolving threat reflects cybercriminals quickly adapting supply-chain attack strategies, previously seen in software ecosystems, now within the emerging AI skill domain.

What Steps Should Affected Users Take?

Even though platforms like Vercel and Microsoft have removed the identified malicious skills from public registries, users who installed them remain vulnerable as the malicious code resides locally in their environments. Those impacted need to manually identify and uninstall these rogue AI skills immediately to prevent further credential exposure. Moreover, reviewing and rotating any potentially compromised keys and tokens is necessary to mitigate risk.

Practical Takeaway: Protecting Your Systems from AI Skill Attacks

What OpenClaw reveals about agentic AI security risks
What OpenClaw reveals about agentic AI security risks

This incident underscores the importance of cautious adoption of third-party AI skills, especially from less vetted sources. Users and organizations should treat AI skill installations with the same scrutiny as traditional software packages, ensuring only trusted, verified skills are used. Regular audits of installed AI skills and proactive credential management help reduce the risk posed by such increasingly sophisticated supply-chain attacks leveraging AI technologies.

React to this story

Related Posts